x-agents-cross-review

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The review purpose is coherent, and most referenced tools fit that purpose, but the skill is over-privileged: it spawns multiple background agents with bypassPermissions and full tool access while processing untrusted PR/spec/code content. That makes prompt-injection and unintended autonomous actions the primary risks, with moderate data exposure risk and only low-to-moderate supply-chain concern from the underspecified curl usage.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
May 1, 2026, 12:55 AM
Package URL
pkg:socket/skills-sh/laststance%2Fskills%2Fx-agents-cross-review%2F@5c2d98025f7be8b1d40fb724e79312e685f8ee2e